Apple Safari Fixes Cross-Origin Issue to Protect Users' Data
CVE-2024-44187
6.5MEDIUM
Key Information:
Summary
A vulnerability exists in Apple products due to improper handling of 'iframe' elements, which can lead to cross-origin data exfiltration. This security issue could enable malicious websites to unintentionally access sensitive user data from other domains. Apple has addressed this vulnerability in several updates, including Safari 18, visionOS 2, watchOS 11, macOS Sequoia 15, iOS 18, iPadOS 18, and tvOS 18, emphasizing the importance of keeping software up to date for personal data protection.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published